Описание
A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
A flaw was found in jackson-coreutils. This server-side request forgery (SSRF) vulnerability occurs when applications use the JsonLoader.fromURL function with untrusted input. A remote attacker can exploit this to induce the server to make arbitrary requests. This could lead to unauthorized information disclosure or access to internal network resources.
Отчет
Moderate: A server-side request forgery (SSRF) vulnerability exists in jackson-coreutils when applications use JsonLoader.fromURL with untrusted input. This flaw allows a remote attacker to induce the server to make arbitrary requests, potentially leading to information disclosure or access to internal network resources. The impact is considered Moderate due to the need for an application to expose this functionality to untrusted input.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | jackson-coreutils | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | jackson-coreutils | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk11-openshift-rhel8 | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 8 | jackson-coreutils | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jackson-coreutils | Fix deferred | ||
| Red Hat Single Sign-On 7 | jackson-coreutils | Out of support scope |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
5.3 Medium
CVSS3